Junglewise Threat Intelligence

CVE-2026-58601: Microsoft Windows privilege escalation in VHD Miniport Driver

CVE-2026-58601 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 11 Version 25H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 23H2, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows component responsible for managing Virtual Hard Disks (VHD). An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows Virtual Hard Disk (VHD) Miniport Driver. The vulnerability is triggered when the driver improperly handles memory allocation or data copying during VHD operations. An attacker with low-privileged local access can exploit this flaw to execute code in kernel mode, leading to a full local privilege escalation (LPE). The attack vector is local, requiring no user interaction, and has been assigned a CVSS score of 7.8. Microsoft has released security updates to address this issue across affected Windows 10 and 11 versions.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2525

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats